verify / verify (push) Successful in 4m29s
Reviewed source export adds verified TLS mail, encrypted outbox, mailbox verification and password reset protocols. Preserve public ancestry; omit local development history and operational queue. Consumer deployment and inbox delivery proof remain separate.
365 lines
20 KiB
Markdown
365 lines
20 KiB
Markdown
<!-- SPDX-License-Identifier: MPL-2.0 -->
|
||
|
||
# Changelog
|
||
|
||
## v0.1.0-preview.28 — 2026-09-11
|
||
|
||
- Add bounded single-recipient SMTP with verified TLS, a fixed sender and
|
||
secret-free diagnostics, plus an explicit encrypted SQLite transactional outbox.
|
||
Cover cancellation, retry/lease recovery, idempotency and payload expiry locally.
|
||
- Add optional verified-mailbox, both-mailbox address-change and password-reset
|
||
protocols with a separate explicit SQLite migration, atomic audits/mail intent,
|
||
session/credential/replay checks and preserved passkeys, ownership and history.
|
||
Consumer HTTP/UI integration is locally verified; deployment and real delivery
|
||
proof remain separate consumer checkpoints.
|
||
- Document and test optional CMS classification and relationships, including
|
||
unclassified publication and clearing associations with preserved history.
|
||
No runtime behavior or schema change.
|
||
- Keep the existing passkey algorithm regression tests in the public export.
|
||
|
||
## v0.1.0-preview.27 — 2026-09-10
|
||
|
||
- Add independent `cms` values and a `cmssqlite` adapter for named taxonomies,
|
||
stable terms, immutable revision associations and bidirectional editorial
|
||
links. Applications retain typed content, templates, permissions and commerce.
|
||
- Join caller-owned SQLite transactions so content, publication pointers and
|
||
application audits commit together. Schema installation is explicit and
|
||
independent of authentication schema 11, which remains unchanged.
|
||
- Preserve term URL aliases and historical associations on rename/retirement.
|
||
Query only published snapshots, with namespace isolation and bounded keyset
|
||
pagination. The application still checks each target's current availability.
|
||
- Include executable integration guidance and regressions for conflicts,
|
||
rollback, draft isolation, reverse discovery, aliases and retirement. The
|
||
consumer exercised native editing and publication behind trusted local TLS.
|
||
|
||
## v0.1.0-preview.26 — 2026-09-05
|
||
|
||
- Add optional self-profile readers and revision-checked username/display-name
|
||
writes. Recheck the active session, account and expected revision atomically
|
||
with a secret-free audit; preserve immutable user identity and ownership.
|
||
- Username edits revoke other sessions but preserve the acting session. A
|
||
password-confirmed write can require the exact verified credential hash,
|
||
rejecting a concurrent password reset. Applications own reauthentication,
|
||
operation-bound passkey approval, CSRF/origin checks and rate/concurrency limits.
|
||
- Add explicit SQLite schema 11 for monotonic profile revisions. Existing rows
|
||
begin at revision 1; startup with migrations disabled rejects older schemas.
|
||
Do not run older writers against schema 11 as a database rollback strategy.
|
||
- Email changes are deliberately absent; pending-address verification and mail
|
||
delivery are separate work. Test invalid/restricted sessions, collisions,
|
||
concurrent/stale edits, audit rollback, restart and schema-10 migration.
|
||
|
||
## v0.1.0-preview.25 — 2026-09-05
|
||
|
||
- Add optional, credential-free user and organization directory readers for
|
||
application-authorized instance administration. They include inactive/pending
|
||
users and personal/archived organizations independently of membership.
|
||
- Bound literal searches and stable-ID pagination to at most 200 returned
|
||
records. Queries do not load passwords, sessions, recovery material, invitations
|
||
or role grants; they grant no authority. Applications must authorize each read.
|
||
- Cover pagination, renamed records, literal SQL/wildcard input, Unicode text,
|
||
invalid bounds and cancellation. Schema 10 and existing repository contracts
|
||
remain unchanged; source exports include the new optional interfaces/readers.
|
||
|
||
## v0.1.0-preview.24 — 2026-09-05
|
||
|
||
- Add explicit owner-managed profile and optimistic membership operations.
|
||
Current direct ownership is checked inside the SQLite write transaction even
|
||
when the target is an ordinary member. Active account/membership, non-personal
|
||
organization, last-owner, optimistic state, and atomic audit requirements remain
|
||
intact. Existing delegated-administrator APIs retain their behavior.
|
||
- Require `OwnerManagedRepository` support without a preflight-only fallback.
|
||
No schema migration is added; schema 10 remains current.
|
||
- Test revoked, narrowed, suspended, removed and incomplete actor authority,
|
||
archived/personal organizations, stale and concurrent submissions, and rollback
|
||
of profile, membership, team, role and invitation effects after audit failure.
|
||
|
||
## v0.1.0-preview.23 — 2026-09-05
|
||
|
||
- Add atomic direct organization role sets with optimistic binding IDs, current
|
||
direct-owner authorization, last-owner protection, and a single audit. Roles
|
||
may be combined without changing narrower or team grants.
|
||
- Add bounded multiple-role invitations and opt-in owner-managed invitation
|
||
policy. Persist the required grantor authority and recheck it at acceptance,
|
||
together with active, fully registered users and recipient email. Suspended
|
||
members cannot reactivate themselves by accepting an older invitation.
|
||
- Invitations enroll new members rather than adding permissions to existing
|
||
members. Membership removal revokes pending invitations for that recipient
|
||
in the same transaction, preventing an older offer from restoring access.
|
||
- Add SQLite schema 10 for invitation role sets and stored owner authority.
|
||
Legacy single-role data remains readable after explicit migration; older
|
||
schema-9 applications are not approved writers of the migrated database.
|
||
Custom repositories must implement the role-set extensions before exposing
|
||
these operations; there is no non-atomic fallback.
|
||
- Include the owned-organization implementation and tests in the public-source
|
||
export, and compile the exported tree to catch incomplete source distributions.
|
||
- Cover competing changes and invitation acceptance, failure rollback, stale
|
||
owners, unsupported adapters, and migration of legacy invitations.
|
||
|
||
## v0.1.0-preview.22 — 2026-09-04
|
||
|
||
- Add `organizations.CreateOwnedOrganization` for atomic creation of an existing
|
||
user's organization, initial membership, direct configured owner role, and
|
||
correlated organization/access audits.
|
||
- Require an active, fully registered owner and a pre-seeded role inside the
|
||
SQLite transaction. Missing storage support fails without a non-atomic fallback.
|
||
- Preserve the older membership-only creation API and schema version 9. Customer
|
||
and merchant permissions remain application-owned, with no commerce dependency.
|
||
- Exercise failure at every write stage, concurrent duplicate creation, scoped
|
||
access, restart recovery, last-owner protection, and mismatched authority/audits.
|
||
|
||
## v0.1.0-preview.21 — 2026-09-04
|
||
|
||
- Derive the registered credential algorithm from the verified COSE public key
|
||
embedded in authenticator data instead of the optional browser
|
||
`publicKeyAlgorithm` convenience member.
|
||
- Preserve the ES256-only policy while accepting standards-compliant response
|
||
serializers that omit redundant response conveniences, including the
|
||
Bitwarden/Vaultwarden passkey flow exercised through Gamertan.
|
||
- Add regression coverage for an ES256 credential whose convenience algorithm
|
||
is absent, plus malformed and non-ES256 credential rejection.
|
||
|
||
## v0.1.0-preview.20 — 2026-09-04
|
||
|
||
- Extend the direct-owner transaction boundary to invitations. Creating or
|
||
revoking an invitation that grants the configured owner role now requires
|
||
the actor to remain an active direct owner after the SQLite write lock is
|
||
acquired.
|
||
- Preserve application-owned permission policy for ordinary invitations while
|
||
preventing a broad access-management role, stale ceremony, or alternate
|
||
repository call from creating or cancelling owner access.
|
||
- Pass the configured owner role explicitly through invitation repository
|
||
mutations so non-SQLite adapters cannot silently omit the invariant.
|
||
|
||
## v0.1.0-preview.19 — 2026-09-04
|
||
|
||
- Require a current active direct owner for every direct-role transition to or
|
||
from the configured owner role. The SQLite adapter rechecks that authority
|
||
after acquiring its write lock, preventing a role manager from promoting
|
||
itself or changing an owner through a stale application authorization.
|
||
- Apply the same transactional owner-authority boundary to membership
|
||
suspension, reactivation, and removal, including the legacy lifecycle
|
||
methods. Non-owner administrators may still manage non-owner members while
|
||
last-owner protection remains a separate invariant.
|
||
- Expose stable owner-authority errors so applications can distinguish an
|
||
authorization drift conflict from malformed input or storage failure.
|
||
|
||
## v0.1.0-preview.18 — 2026-09-04
|
||
|
||
- Add owner-assisted account recovery for a documented human-review path when
|
||
normal password, passkey, and recovery-code authentication is unavailable.
|
||
Issuance requires an active direct organization owner and returns a bounded,
|
||
single-use, 15-minute secret while persisting and auditing only its digest.
|
||
- Invalidate the recovered member's existing password, passkeys, recovery
|
||
codes, sessions, ceremonies, and older recovery grants when the reviewed
|
||
enrollment is issued. Completion atomically installs one replacement
|
||
password, passkey, and recovery-code set without issuing a normal session.
|
||
- Keep identity and organization-visible recovery audits in the same SQLite
|
||
transactions as their credential changes, and document the application
|
||
boundary for fresh passkey authorization, secret-fragment delivery, and
|
||
human evidence review.
|
||
|
||
## v0.1.0-preview.17 — 2026-09-04
|
||
|
||
- Add optimistic organization-membership suspension, reactivation, and
|
||
removal for fresh-authentication administration flows. The exact displayed
|
||
membership state is rechecked after acquiring the SQLite write lock, so a
|
||
concurrent or stale ceremony fails without changing access or writing an
|
||
audit event.
|
||
- Keep membership lifecycle consequences transactional: suspension removes
|
||
team membership, removal also revokes direct bindings, reactivation does not
|
||
silently restore former teams, and every successful change appends its
|
||
organization-visible audit before commit.
|
||
- Strengthen last-owner protection to require another active direct owner
|
||
whose platform account is also active. Existing storage adapters retain the
|
||
legacy interface; security-sensitive applications fail closed unless their
|
||
repository implements the optimistic lifecycle extension.
|
||
|
||
## v0.1.0-preview.16 — 2026-09-03
|
||
|
||
- Add bounded organization-member and direct user-role listings for
|
||
application-owned access administration pages. Direct listings deliberately
|
||
exclude team and narrower resource grants rather than flattening distinct
|
||
authority into one apparent role.
|
||
- Add atomic direct-role replacement with exact expected-binding checks,
|
||
transactional access audit, active-member validation, and final active
|
||
direct-owner protection. SQLite serializes competing replacements so stale
|
||
administration fails with a stable conflict instead of partially applying.
|
||
- Record the Gamertan administration dogfood boundary: applications authorize
|
||
the route and fresh passkey assertion, while Foundations owns the reusable
|
||
storage transaction and invariants.
|
||
|
||
## v0.1.0-preview.15 — 2026-09-03
|
||
|
||
- Permit applications to opt into an exact non-default HTTPS WebAuthn origin
|
||
port for `localhost` and reserved `.test` relying-party IDs. The configured
|
||
origin remains exact, production origins remain portless by default, and
|
||
malformed, default, non-canonical, zero, or out-of-range ports fail closed.
|
||
- Record the Gamertan local-Caddy dogfood pressure that required this explicit
|
||
development boundary without weakening cross-origin ceremony rejection.
|
||
|
||
## v0.1.0-preview.14 — 2026-09-03
|
||
|
||
- Reject header-only, truncated, and structurally invalid PDF uploads in the
|
||
bounded media preparer. Accepted attachments now require a supported PDF
|
||
version, terminal EOF marker, numeric in-range `startxref`, and either a
|
||
traditional xref/trailer or xref-stream object at the declared offset.
|
||
- Keep PDF handling storage-neutral and non-rendering: applications still own
|
||
authorization, reference tracking, attachment disposition, and lifecycle.
|
||
|
||
## v0.1.0-preview.13 — 2026-09-03
|
||
|
||
- Complete the password-plus-recovery-code flow with a short-lived restricted
|
||
grant bound into a replacement-passkey ceremony. Completion atomically
|
||
consumes the grant, stores the verified passkey, replaces every recovery
|
||
code, revokes any intervening sessions and ceremonies, and records both
|
||
audits without issuing a normal session.
|
||
- Keep failed completion retryable until grant expiry: a duplicate credential
|
||
or other transaction failure rolls back grant consumption and recovery-code
|
||
replacement, while a mismatched WebAuthn binding consumes only the affected
|
||
ceremony.
|
||
|
||
## v0.1.0-preview.12 — 2026-09-03
|
||
|
||
- Add a root-local bootstrap transaction that creates the first passkey-only
|
||
application owner, non-personal organization, active membership, direct
|
||
owner binding, one-time enrollment digest, and secret-free audit records
|
||
atomically.
|
||
- Fail closed and roll back the entire bootstrap when the application has not
|
||
seeded the configured owner role. The raw enrollment token is returned only
|
||
after commit and never enters repository state or audit records.
|
||
|
||
## v0.1.0-preview.11 — 2026-09-03
|
||
|
||
- Add expected-user completion for authenticated self-service passkey
|
||
enrollment. A mismatched ceremony is consumed and fails before credential
|
||
persistence, closing an authorization seam found while dogfooding Gamertan's
|
||
account security page.
|
||
|
||
## v0.1.0-preview.10 — 2026-09-03
|
||
|
||
- Add atomic public-account registration with required canonical email,
|
||
password authentication, printable recovery codes, a personal organization,
|
||
direct owner access, and an optional initial passkey. Pending registrations
|
||
cannot authenticate, and abandoned drafts expire without reserving identity
|
||
fields indefinitely.
|
||
- Add password verification without session issuance plus operation-bound
|
||
WebAuthn completion hooks, allowing applications to require fresh passkeys
|
||
for sensitive actions without imposing passkeys on ordinary customer use.
|
||
- Add digest-only recovery-code persistence and short-lived, single-use
|
||
recovery grants that consume a code and revoke existing sessions atomically.
|
||
- Add bounded raster/PDF media preparation and a hardened content-addressed
|
||
local filesystem adapter with atomic writes, private modes, and symlink
|
||
rejection.
|
||
- Add explicit SQLite open-without-migration and schema-requirement APIs while
|
||
preserving the historical migrating `Open` behavior for existing adopters.
|
||
- Record application dogfood findings and the independent future commerce
|
||
module boundary.
|
||
|
||
## v0.1.0-preview.9 — 2026-09-03
|
||
|
||
- Add a documented root package and executable composition example so the
|
||
module landing page presents its purpose, package-selection guidance,
|
||
security model, and `net/http` integration rather than only a directory
|
||
index.
|
||
- Add the repository's default MPL-2.0 licence at the conventional root path
|
||
so Go package tooling can identify the library licence while preserving the
|
||
existing file-level exceptions for starters and operational machinery.
|
||
- Rework the public README around progressive adoption, explicit design
|
||
promises, package selection, assurance gates, and canonical project links.
|
||
|
||
## v0.1.0-preview.8 — 2026-08-28
|
||
|
||
- Preserve `http.Hijacker` through the request-evidence middleware so audited,
|
||
authenticated WebSocket and other HTTP upgrade handlers can operate without
|
||
bypassing request logging. Successful upgrades are recorded as HTTP 101;
|
||
upgraded-protocol bytes remain outside HTTP body-byte accounting.
|
||
|
||
- Add revisioned active/archived lifecycles for organizations and teams,
|
||
invitation listing and revocation, membership suspension/removal, team-member
|
||
removal, and transactional organization-visible audit events.
|
||
- Make archived organizations and teams ineffective during authorization and
|
||
preserve the final active direct owner during membership changes.
|
||
- Allow invitations to carry one bounded direct role and reviewed team
|
||
memberships, applied atomically with single-use acceptance.
|
||
- Add an atomic password-to-passkey migration ceremony that stores the first
|
||
passkey, retires the password credential, revokes all sessions, and records
|
||
the migration audit event in one transaction.
|
||
|
||
## v0.1.0-preview.6 — 2026-08-24
|
||
|
||
- Add an explicit mode-`0640` JSONL option for applications that authorize one
|
||
narrowly scoped collector group, while keeping private mode `0600` as the
|
||
default and rejecting permissive modes.
|
||
- Document the setgid-directory ownership boundary for Observatory-style
|
||
collection without granting the collector broader application access.
|
||
- Make vendored dependency and public-snapshot verification portable across
|
||
the maintained Linux gate and native macOS development environments.
|
||
- Keep Previews 1–5 immutable; applications select Preview 6 explicitly when
|
||
adopting collector-readable request evidence.
|
||
|
||
## v0.1.0-preview.5 — 2026-08-21
|
||
|
||
- Add storage-neutral passkey registration, discoverable login, and
|
||
operation-bound fresh assertions without adding self-registration, password
|
||
fallback, TOTP, email recovery, or application-owned routes.
|
||
- Require exact HTTPS relying-party origins, user verification, discoverable
|
||
credentials, no attestation conveyance, and an initial ES256-only algorithm
|
||
policy.
|
||
- Add transactional SQLite credential, ceremony, enrollment, recovery, and
|
||
last-credential protections with atomic single-use consumption.
|
||
- Add a neutral session-issuance boundary for independently verified
|
||
credentials while retaining existing password behavior.
|
||
- Pin WebAuthn protocol verification to `github.com/go-webauthn/webauthn`
|
||
`v0.17.1` and record its source identity, module checksums, licence, and
|
||
transitive security boundary.
|
||
- Add self-service passkey enrollment and removal primitives with fresh
|
||
assertion, session revocation, and last-credential protection.
|
||
- Keep Previews 1–4 immutable; applications select Preview 5 explicitly when
|
||
adopting the passkey boundary.
|
||
|
||
## v0.1.0-preview.4 — 2026-08-18
|
||
|
||
- Add an explicit local-administrator password recovery operation without
|
||
adding a public recovery endpoint or network protocol.
|
||
- Atomically install a one-time Argon2id credential, restore mandatory password
|
||
rotation, revoke every session, and append a secret-free audit event.
|
||
- Prove transaction rollback when the audit event cannot commit and document
|
||
private mode-`0600` delivery as application-owned policy.
|
||
- Keep Previews 1–3 immutable; applications select Preview 4 explicitly when
|
||
adopting administrative recovery.
|
||
|
||
## v0.1.0-preview.3 — 2026-08-18
|
||
|
||
- Add cryptographically generated temporary credentials and an explicit
|
||
password-change-required account state.
|
||
- Replace credentials, clear the requirement, and revoke all existing sessions
|
||
in one repository transaction after verifying the current password.
|
||
- Migrate existing SQLite users with the new requirement disabled; applications
|
||
continue to own first-login routing, private credential delivery, and audit
|
||
policy.
|
||
- Keep Preview 1 and Preview 2 immutable; applications select Preview 3
|
||
explicitly when adopting forced bootstrap rotation.
|
||
|
||
## v0.1.0-preview.2 — 2026-08-17
|
||
|
||
- Add storage-neutral organizations, teams, projects, environments, services,
|
||
single-use invitations, and independently scoped access roles.
|
||
- Separate platform-level authentication roles from organization data access.
|
||
- Add expiring break-glass grants with transactional organization-visible audit
|
||
events and a no-CGO SQLite implementation.
|
||
- Keep `v0.1.0-preview.1` immutable; applications adopt these additive packages
|
||
by explicitly selecting Preview 2.
|
||
|
||
## v0.1.0-preview.1 — 2026-08-16
|
||
|
||
- Establish independent request metadata, logging, browser security, abuse,
|
||
authentication, SQLite, and analytics package boundaries.
|
||
- Add a minimal 0BSD `net/http` starter.
|
||
- Fail closed when unsafe requests lack same-origin evidence or authentication
|
||
middleware is constructed with invalid cookie/service configuration.
|
||
- Bound untrusted request-record byte and duration fields before aggregation.
|
||
- Support Linux as the maintained release platform; native Windows is not a
|
||
release gate or compatibility promise.
|
||
|
||
No compatibility promise is made before a stable release.
|